Symantec Access Management

 View Only

 Ver. Up when we forget your EncryptionKey in SiteMinder

MARUBUN SUPPORT's profile image
MARUBUN SUPPORT posted Jul 26, 2024 09:05 AM

Hi team,

Our customer has following questions.
I would appreciate your reply or advice.


[Poducts]
SiteMinder 12.8 SP07

[Questions]
The customer is planning to upgrade SiteMinder.
However, the they forgot the value of the current version's EncryptionKey.
For this reason, they are considering migrating environments where the Encryption Key is different between the current version and after the version upgrade as follows:

- To migrate the policy store from the current version environment, the policy store will be prepared in a separate database, an XML file will be output using the XPSExport command, and the XML will be imported using the XPSImport command.
-In order to achieve SSO between WebAgents connected in the current version and the upgraded system, they are planning an upgrade that assumes a scenario in which re-authentication will not be required by sharing the keystore.

They have the following thoughts on this scenario.
Please advise if the following thoughts are correct.

- They believe it is possible to migrate the policy store from the current version to the new environment.
   Is this correct?
- They believe that there is no difference in the trusted information of the ported WebAgent between the current version and after the version upgrade.
  Is this correct?
- Will the password information in the user store differ?
- They believe that the EncryptionKey value is not used to analyze the key store information.
  Is SSO possible with the WebAgent even between policy servers with different EncryptionKey values?

Please let me know if there is a way to update the version if they forget the encryption key value.


Best Regards
Marubun Support